Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 10 of 14

Showing resources 136 to 150 of 202.

Open source software and the CRA / 10

How Downstream Manufacturers Should Handle Open Source Components

Learn how downstream manufacturers should handle open-source components under the Cyber Resilience Act, including due diligence, component vulnerabilities, upstream notification, remediation, SBOMs and security attestations.

READ GUIDE
Open source software and the CRA / 11

CRA Documentation for Open Source Components

Understand what CRA documentation manufacturers should maintain for open-source components, including SBOMs, architecture relationships, cybersecurity risk assessments, vulnerabilities, disclosure policies and secure update processes.

READ GUIDE
Secure product development / 12

Managing Secrets and Credentials in CRA-Covered Products

Learn how secrets and credentials should be managed throughout CRA product development, including provisioning, storage, uniqueness, rotation, revocation, reset, build secrets and release evidence.

READ GUIDE
Secure product development / 13

Secure Configuration Management Under the CRA

Learn how to manage secure product configuration throughout the CRA development lifecycle, including baselines, change control, configuration drift, variants, release verification and configuration evidence.

READ GUIDE
Secure product development / 14

Authentication and Access-Control Design Under the CRA

Learn how authentication and access-control architecture can support CRA requirements, including identity models, authorisation, least privilege, administrative access, service identities, recovery and access-control testing.

READ GUIDE
Technical documentation / 09

CRA Product Architecture Documentation

Learn how to document product and system architecture for Cyber Resilience Act technical documentation, including software components, interfaces, data flows, trust boundaries, dependencies, security functions and version-specific architecture evidence.

READ GUIDE
Technical documentation / 10

CRA Security Design Documentation

Learn how to document security design decisions for Cyber Resilience Act technical documentation, including security requirements, architecture controls, trust boundaries, secure defaults, cryptography, resilience, updates and Annex I traceability.

READ GUIDE
Technical documentation / 11

Documenting Security Test Results

Learn how to document Cyber Resilience Act security test results for Annex VII technical documentation, including test scope, product version, environment, Annex I mapping, methods, findings, remediation and retesting.

READ GUIDE
Open source software and the CRA / 12

Donations, Sponsorship and Commercial Activity Under the CRA

Understand how donations, sponsorship, grants, corporate contributions and recurring financial assistance affect the Cyber Resilience Act commercial-activity analysis for free and open-source software.

READ GUIDE
Open source software and the CRA / 13

Preparing an Open Source Project for CRA-Related Requests

Learn how an open-source project can prepare for Cyber Resilience Act related requests from market surveillance authorities, downstream manufacturers and security researchers without assuming manufacturer obligations that do not apply.

READ GUIDE
Secure product development / 15

Cryptography and the Cyber Resilience Act

Understand how cryptographic design supports Cyber Resilience Act requirements, including confidentiality, integrity, update verification, algorithm selection, key management, certificates, randomness and cryptographic agility.

READ GUIDE
Secure product development / 16

Designing Products for Secure Updating

Learn how to design a CRA-ready security update architecture covering update authenticity, integrity, signing keys, safe installation, automatic updating, rollback, recovery, version targeting and secure distribution.

READ GUIDE
Secure product development / 17

How to Build a CRA-Compliant Secure Development Lifecycle

A practical framework for building a CRA-aligned secure development lifecycle covering cybersecurity risk assessment, requirements, architecture, coding, security reviews, testing, release, maintenance and compliance evidence.

READ GUIDE
Technical documentation / 12

Documenting Vulnerability Handling Processes

Learn how to document Cyber Resilience Act vulnerability handling processes for Annex VII technical documentation, including SBOM management, vulnerability intake, coordinated disclosure, remediation, security updates and evidence.

READ GUIDE
Technical documentation / 13

Maintaining Technical Documentation After Product Changes

Learn how Cyber Resilience Act technical documentation should be maintained after software, architecture, production, dependency, security-control and conformity-reference changes.

READ GUIDE